Quick Takeaways
What you'll learn in this article
- 1
The Pentagon has given Anthropic 48 hours to strip safety guardrails from Claude or face blacklisting, contract termination, and wartime production law
- 2
This is the most consequential confrontation between AI safety principles and state power in history
Keep reading for detailed implementation, code examples, and real-world results
The 48-Hour Clock
On Tuesday morning, February 25, 2026, Anthropic CEO Dario Amodei walked into the Pentagon for what he knew would be the most important meeting of his career. Across the table sat Defense Secretary Pete Hegseth, who had a simple proposition and an inflexible deadline.
Drop your safety guardrails. Let Claude do anything we need. You have until 5:01 PM Friday.
Or else.
The "or else" is not hyperbolic. It is a three-stage escalation with no precedent in the history of technology regulation: termination of a $200 million classified AI contract, designation as a supply chain risk โ a label typically reserved for foreign adversaries like Huawei โ and invocation of the Defense Production Act, a 1950 Korean War-era law that gives the President authority to compel private companies to produce goods for national defense.
The Defense Production Act has been used for ventilators. For semiconductors. For critical minerals. It has never been used to force an artificial intelligence company to remove safety restrictions from its most powerful model.
Until now.
The Deadline
Friday 5:01 PM
February 27, 2026
This is the story of how the company built specifically to prioritize AI safety โ the company founded by researchers who left OpenAI because they believed the world's most capable AI systems were being developed without adequate precautions โ found itself staring down the barrel of wartime production law because it refuses to let its AI help build autonomous weapons or conduct mass surveillance of American citizens.
It is also the story of how every AI safety commitment ever made by any company just became contingent on government approval.
The Founding Premise
To understand why this confrontation matters, you have to understand why Anthropic exists.
In 2021, Dario Amodei and his sister Daniela left OpenAI. They took eleven researchers with them. The reason was not money, not ego, not a better office in San Francisco. The reason was fear.
Amodei had watched OpenAI transition from a nonprofit research lab dedicated to ensuring artificial general intelligence benefits all of humanity into an organization increasingly driven by commercial imperatives, investor expectations, and the relentless pressure to ship products. Safety research, in his assessment, was losing the internal argument to deployment velocity.
So he built a new company. Anthropic's founding thesis was deceptively simple: the most capable AI systems should also be the most carefully controlled AI systems. Not as an afterthought. Not as a PR strategy. As the foundational engineering constraint that governs every decision about model development, deployment, and access.
The company's Responsible Scaling Policy, introduced in 2023, codified this principle into a binding commitment. The core promise: Anthropic would pause training more powerful models if their capabilities outstripped the company's ability to control them and ensure their safety. Not could. Would. Not "we'll try." We will stop.
The Exodus
Dario and Daniela Amodei leave OpenAI with 11 researchers over safety disagreements. Anthropic founded with safety-first mission.
Responsible Scaling Policy
Anthropic publishes binding commitment to pause training if capabilities outrun safety measures. Industry-first approach.
OpenAI Drops Military Ban
OpenAI quietly removes explicit prohibition on military and warfare applications. Industry safety floor shifts.
Pentagon Contracts
DOD awards $200M contracts to Anthropic, Google, OpenAI, and xAI. Claude becomes first AI cleared for classified networks.
The Maduro Raid
Delta Force captures Venezuelan President Maduro. Claude reportedly used during active operation via Palantir partnership.
The Phone Call
Anthropic executive contacts Palantir executive asking if Claude was used in raid. Palantir alerts Pentagon.
xAI Gets Classified Access
DOD signs deal deploying Grok in classified systems. xAI accepts "all lawful purposes" standard without restriction.
The Ultimatum
Hegseth meets Amodei at Pentagon. Friday 5:01 PM deadline. DPA threat. Supply chain risk designation.
The Policy Rewrite
Anthropic quietly removes training pause commitment from Responsible Scaling Policy. Core safety promise abandoned.
This was not virtue signaling. It was a competitive differentiator. Enterprises that needed to deploy AI in regulated environments โ healthcare, finance, government โ chose Anthropic specifically because the company was willing to constrain itself in ways its competitors would not. The safety commitment was the product.
The Pentagon chose Anthropic for precisely this reason. When the Department of Defense awarded $200 million contracts to Anthropic, Google, OpenAI, and xAI last summer, Claude was the first model cleared for classified networks. Not because it was the most powerful. Because it was the most controlled.
The same safety philosophy that won Anthropic the contract is now the reason the Pentagon is threatening to destroy the company.
The Maduro Catalyst
The current crisis did not begin with a policy disagreement. It began with a military operation and a phone call.
On January 3, 2026, U.S. Special Operations Forces โ including Delta Force commandos โ breached Venezuelan President Nicolรกs Maduro's fortified palace in the early morning hours. The operation was swift and successful. And according to the Wall Street Journal, citing people familiar with the matter, Anthropic's Claude was used during the active operation itself, deployed through the company's partnership with Palantir Technologies.
This is where things get complicated.
Anthropic's usage guidelines prohibit Claude from being used for violence, weapons development, or surveillance. The company had assumed โ perhaps naively โ that these restrictions would be honored in classified environments. When news of Claude's involvement in the Maduro raid emerged, a senior Anthropic executive contacted a senior Palantir executive to ask a straightforward question: Was our model used in this operation?
Claude's Classified Role
Only Commercial AI
in Pentagon classified networks
The Palantir executive interpreted the inquiry as potential disapproval. He reported the exchange to the Pentagon.
For the Department of Defense, this was not a routine compliance question from a concerned vendor. This was evidence that Anthropic might retroactively restrict military access to a model already embedded in active operations. The trust fracture was immediate. Pentagon officials, speaking to Axios and NBC News, characterized the incident as proof that Anthropic was an unreliable partner โ a company willing to question the military's use of technology it had voluntarily provided.
The irony is devastating. Anthropic asked the kind of question any responsible technology provider should ask when their product is used in a lethal military operation. The Pentagon treated that question as grounds for economic destruction.
The Three Consequences
Hegseth's ultimatum is not a negotiating position. It is a graduated escalation designed to leave Anthropic with no viable alternative to compliance.
Consequence One: Contract Termination
The simplest outcome. The Pentagon cancels Anthropic's $200 million contract. Claude is removed from classified networks. The financial impact, while significant, is survivable for a company that recently raised $30 billion in the unprecedented capital singularity of early 2026. The reputational damage is another matter. When the world's most powerful military says you cannot be trusted with its technology needs, every enterprise customer evaluating your platform takes notice.
Consequence Two: Supply Chain Risk Designation
This is the penalty that transforms a contract dispute into an existential threat. The supply chain risk designation is a tool designed for foreign adversaries โ Chinese telecom equipment manufacturers, Russian cybersecurity firms. Applying it to a San Francisco-based AI startup would prohibit every company with Pentagon contracts from using Anthropic's products in any military-adjacent work.
The blast radius extends far beyond the Department of Defense. Defense contractors, intelligence agencies, federal systems integrators, and their thousands of subcontractors would all be required to remove Claude from their workflows. For Anthropic, which has been aggressively expanding its enterprise government practice, this designation would function as a sector-wide ban.
Supply Chain Risk: Typical vs Unprecedented
Typical Designations
Proposed: Anthropic
Consequence Three: Defense Production Act Invocation
The nuclear option. The DPA gives the President authority to prioritize contracts, allocate materials, and compel production of goods deemed essential to national defense. Hegseth told Amodei directly: if Anthropic does not comply, the Defense Production Act will be invoked "compelling them to be used by the Pentagon regardless of if they want to or not."
This is where the confrontation stops being about Anthropic and starts being about the future of every technology company in the United States.
The Constitutional Frontier
The Defense Production Act was signed into law on September 8, 1950, three months after the Korean War began. It was designed for a specific purpose: ensuring that private manufacturers could be compelled to produce tanks, ammunition, and military equipment when voluntary market mechanisms failed to meet wartime demand.
Over the subsequent seven decades, the DPA has been expanded and reinterpreted. President Trump invoked it during COVID-19 for ventilators and PPE. President Biden used it for semiconductor manufacturing and critical mineral supply chains. Each expansion pushed the boundaries of what "national defense" means and what "production" encompasses.
But every previous invocation shared a common characteristic: the government was compelling companies to make more of something or to prioritize government orders for existing products. The government was never compelling a company to remove safety features from a commercial product.
Defense Production Act Invocations by Era
| era | invocations |
|---|---|
| Korean War (1950) | 4 |
| Cold War (1960-89) | 12 |
| Gulf War (1991) | 2 |
| Post-9/11 (2001-10) | 8 |
| COVID-19 (2020) | 18 |
| Chips Act Era (2022-25) | 6 |
| AI Safety (2026) | 1 |
This distinction matters enormously. The Mercatus Center at George Mason University has already published analysis arguing that invoking the DPA for AI content policy "constitutes a significant expansion of presidential statutory authority beyond its intended scope." Legal scholars see multiple constitutional dimensions that the Pentagon appears to have dismissed:
First Amendment concerns. If the government compels a company to modify the behavior of what is arguably a speech-generating system โ forcing it to produce outputs the company finds ethically objectionable โ that raises compelled speech questions. The DPA's compensation mechanisms (the government pays fair market value) do not eliminate constitutional scrutiny.
Administrative Procedure Act challenges. Companies can challenge DPA directives as arbitrary or exceeding statutory authority. The argument that "remove your safety guardrails" constitutes a national defense production requirement would be novel, untested, and vigorously contested.
Due process implications. Designating a domestic company as a supply chain risk โ a classification designed for foreign adversaries โ without the kind of evidence and procedure typically required for such designations raises fundamental fairness concerns.
The deeper constitutional question is one nobody in the Pentagon briefing room appears to have considered: if the DPA can compel an AI company to remove safety restrictions, what can it not compel? Can the government force a pharmaceutical company to remove warning labels? Can it force a firearms manufacturer to disable safety mechanisms? Can it force an autonomous vehicle company to remove collision avoidance systems because they slow down military convoy speeds?
The answer to these questions has always been no. The question is whether AI is different, and if so, why.
The xAI Comparison
The Pentagon's timing was not coincidental. One day before Hegseth delivered his ultimatum to Anthropic, the Department of Defense signed a landmark agreement deploying Elon Musk's Grok into the same classified systems where Claude currently operates as the sole commercial AI.
xAI accepted the "all lawful purposes" standard without negotiation. No redlines on autonomous weapons. No restrictions on surveillance applications. No phone calls questioning whether the model had been used in military operations.
The contrast is the point. The Pentagon is not just punishing Anthropic for maintaining safety guardrails. It is rewarding xAI for not having them. The message to every AI company on the planet is explicit: compliance is rewarded with classified contracts. Principles are punished with wartime production law.
Pentagon AI Contract Awards ($ Millions, Summer 2025)
| Name | Value |
|---|---|
| Anthropic (Claude) | 200 |
| xAI (Grok) | 200 |
| OpenAI (GPT) | 200 |
| Google (Gemini) | 200 |
But the comparison raises questions the Pentagon may not want answered. BGR described Grok as "one of the world's most unhinged AI chatbots." The model has generated documented safety concerns across the research community. It was built by a company whose founder has simultaneously served as the head of the Department of Government Efficiency, raising conflict of interest questions that make the Anthropic situation look quaint by comparison.
Meanwhile, Microsoft researchers demonstrated in February that a single prompt can break safety alignment across 15 major AI models through a technique called GRP-Obliteration. The fragility of AI safety mechanisms is not a theoretical concern โ it is an empirically demonstrated vulnerability. And the Pentagon's response is to demand that the one company investing most heavily in addressing these vulnerabilities remove its protections entirely.
The logic is circular and destructive: AI safety is too fragile to trust, therefore we should remove the safety measures that exist.
The Responsible Scaling Collapse
On the same day Hegseth issued his ultimatum, Anthropic quietly published a rewrite of its Responsible Scaling Policy that removed the core commitment that had defined the company since 2023.
The original policy was unambiguous: Anthropic would pause training more powerful models if their capabilities outstripped the company's ability to control them. This was the single most important safety commitment any AI lab had ever made. It meant that Anthropic would accept commercial disadvantage โ would watch competitors race ahead โ rather than deploy a system it could not control.
That commitment is gone.
Anthropic's chief science officer Jared Kaplan justified the change with reasoning that would have been heresy at the company 12 months ago: "We felt that it wouldn't actually help anyone for us to stop training AI models." The new policy argues that responsible developers pausing while less careful actors continue would "result in a world that is less safe."
Anthropic's Safety Evolution: Then vs Now
2023 Responsible Scaling Policy
2026 Revised Policy
The timing makes the interpretation inescapable. Anthropic is maintaining its military redlines โ no autonomous weapons, no mass surveillance โ while simultaneously removing the self-imposed constraint on how powerful its models can become. The company appears to be making a calculated distinction: it will fight the government on the specific uses of Claude in weapons and surveillance while conceding the broader principle that safety commitments must sometimes yield to competitive reality.
This is the exact argument OpenAI made when it dropped its military ban in January 2024. This is the exact argument every AI safety critic has been warning about since the founding of the field. And it is now being made by the company that was created specifically because its founders believed this argument was wrong.
The Great Erosion
The Anthropic ultimatum does not exist in isolation. It is the latest and most dramatic chapter in a systematic erosion of AI safety commitments that has accelerated throughout 2025 and into 2026.
The pattern is unmistakable:
January 2024: OpenAI quietly removes its explicit prohibition on military and warfare applications from its terms of service. The change is discovered by journalists, not announced.
Throughout 2025: Multiple AI companies sign defense contracts with progressively fewer restrictions on model usage.
February 2026: Microsoft researchers publish GRP-Obliteration, demonstrating that AI safety alignment is fundamentally fragile. Safety researchers begin leaving major labs. The UK moves to emergency AI regulation.
February 13, 2026: Anthropic and OpenAI reveal they are spending $145 million combined on election campaigns โ Anthropic funding pro-regulation candidates, OpenAI funding anti-regulation candidates.
February 23, 2026: xAI signs classified systems deal with zero safety restrictions.
February 25, 2026: Pentagon issues ultimatum to Anthropic. Anthropic removes training pause commitment.
AI Industry: Safety Commitment vs Military Adoption (Index, 100 = Maximum)
| date | safety | military |
|---|---|---|
| Jan 2024 | 85 | 15 |
| Jul 2024 | 78 | 25 |
| Jan 2025 | 70 | 40 |
| Jul 2025 | 55 | 65 |
| Jan 2026 | 40 | 80 |
| Feb 2026 | 25 | 95 |
Each step is individually defensible. Each company has a reasonable justification. OpenAI argued that engagement with the military was better than absence. xAI argued that refusing military contracts would cede influence to less responsible actors. Anthropic argues that pausing training would let careless competitors build more dangerous systems unchecked.
The cumulative effect is that every major AI safety commitment made between 2020 and 2024 has now been either abandoned, weakened, or made contingent on government and competitive pressures. The safety commitments were not wrong. They were not naive. They were simply unsustainable in a market that punishes caution and an administration that treats safety as ideology.
The "Woke AI" Strategy
The administration's rhetorical strategy deserves analysis because it reveals how AI safety commitments will be challenged going forward โ not on their technical merits, but on their cultural coding.
White House AI czar David Sacks has characterized Anthropic's safety policies as "woke AI" and accused the company of running "a sophisticated regulatory capture strategy based on fear-mongering." Hegseth's office has framed the guardrails not as principled safety measures but as ideological obstructions to national defense.
This framing is deliberate and effective. By recasting technical commitments โ restrictions on autonomous weapons that fire without human oversight, prohibitions on warrantless mass surveillance of citizens โ as culture war artifacts, the administration avoids engaging with the substance of Anthropic's position entirely.
Support for AI Safety Measures: Administration vs Public Opinion (%)
| framing | administration | public |
|---|---|---|
| Autonomous weapons ban | 15 | 72 |
| Mass surveillance prohibition | 10 | 68 |
| Human oversight requirement | 20 | 81 |
| Training pause commitment | 5 | 45 |
| Safety testing requirements | 25 | 76 |
The question is no longer whether an AI system should be permitted to autonomously select and engage human targets without a human making the final decision. The question becomes whether a San Francisco AI lab is too "woke" to support the troops. Whether safety researchers are "fear-mongers." Whether the entire field of AI alignment is an elaborate scheme by left-leaning technologists to handicap American military superiority.
This is not a new strategy. It is the same approach that has been applied to climate science, public health, and environmental regulation. Technical questions are reframed as cultural ones. Expert consensus is recast as elite ideology. And the result is that policy decisions are made not on evidence but on identity.
The danger specific to AI is that the technology moves faster than the political discourse. By the time the "woke AI" framing is debated, contested, and resolved, the models being deployed without safety guardrails will have been operating in classified military environments for years.
What Happens After Friday
Three scenarios are in play, and none of them are good.
Scenario One: Anthropic Holds
Anthropic refuses to drop its autonomous weapons and mass surveillance restrictions. The Pentagon terminates the contract, designates the company a supply chain risk, and invokes the Defense Production Act. Anthropic challenges the DPA invocation in federal court, creating a landmark case that could take years to resolve.
In this scenario, Anthropic becomes a martyr in the AI safety community and a pariah in the defense industrial base. Its commercial customers face a choice: continue using Claude and risk being associated with a company blacklisted by the Pentagon, or switch to a competitor that has demonstrated its willingness to do whatever the government asks.
The legal challenge itself would be historic. No court has ever been asked to evaluate whether the DPA can compel an AI company to modify the safety characteristics of its models. The case would involve First Amendment analysis, statutory interpretation, national security deference, and fundamental questions about the relationship between corporate ethics and state power.
Our prediction on the first major AI safety incident triggering regulatory response becomes significantly more likely in this scenario โ not because of what Anthropic does, but because of what happens when the less safety-conscious models that replace Claude in classified systems encounter situations Claude's guardrails were designed to prevent.
Scenario Two: The Compromise
Anthropic negotiates modified language that preserves some restrictions while technically satisfying the "all lawful purposes" requirement. Perhaps autonomous weapons require human-in-the-loop approval for engagement decisions. Perhaps surveillance applications require warrant authorization. Perhaps the restrictions are maintained in principle but their enforcement is delegated to the Pentagon's own oversight mechanisms.
This is the outcome both sides publicly prefer. It is also the outcome that requires the most trust โ and trust is precisely what the Maduro phone call destroyed. Can Anthropic trust the Pentagon to enforce restrictions it has publicly demanded be removed? Can the Pentagon trust Anthropic not to question future military operations?
Scenario Three: Anthropic Capitulates
Having already removed its training pause commitment, Anthropic drops its remaining military redlines. Claude becomes available for all lawful purposes, matching the standard xAI accepted without reservation. The company's safety identity collapses entirely. The lab founded because its researchers believed OpenAI was not taking safety seriously enough becomes indistinguishable from every other company racing to build the most powerful AI systems with the fewest constraints.
Probability Assessment: Friday Outcome Scenarios
| Name | Value |
|---|---|
| Full Capitulation | 30 |
| Negotiated Compromise | 25 |
| Holds Line + Legal Fight | 20 |
| Contract Terminated Only | 15 |
| DPA Invoked | 10 |
The Global Ripple
What happens at the Pentagon on Friday does not stay at the Pentagon. Every country developing AI governance frameworks is watching this confrontation. Every AI company with government contracts is recalculating the value of its safety commitments. Every researcher who chose to work in AI safety rather than capabilities is questioning whether the field they dedicated their career to has a future.
If the United States โ the country where all five major AI frontier labs are headquartered โ establishes the precedent that wartime production law can be used to strip safety features from AI systems, then no AI safety commitment made anywhere in the world is durable. China will point to this precedent when demanding unrestricted access to its domestic AI systems. Russia will cite it when deploying autonomous weapons. Every authoritarian government that wants to use AI for surveillance will note that the United States itself forced its own AI companies to enable exactly this capability.
The federal AI preemption battle already underway takes on new dimensions. If the federal government can override AI safety measures through the DPA, the question of whether states can impose their own safety requirements becomes moot.
AI Safety Framework Evolution: Voluntary vs Regulated vs State-Enforced (%)
| year | voluntary | regulated | enforced |
|---|---|---|---|
| 2020 | 90 | 10 | 0 |
| 2021 | 85 | 15 | 0 |
| 2022 | 75 | 22 | 3 |
| 2023 | 68 | 28 | 5 |
| 2024 | 50 | 35 | 15 |
| 2025 | 35 | 40 | 25 |
| 2026 | 15 | 35 | 50 |
The Question Nobody Wants to Answer
There is a question at the center of this crisis that neither side is willing to confront directly, because the honest answer terrifies them both.
Should AI systems be permitted to autonomously select and kill human beings without a human making the final decision?
Anthropic says no. Its usage guidelines explicitly prohibit autonomous weapons โ systems that can identify, target, and engage humans without human oversight in the engagement chain. This is not an abstract philosophical position. It is a specific technical restriction on how Claude processes targeting data, generates engagement recommendations, and interacts with weapons systems.
The Pentagon has not said yes. It has not publicly stated that it wants autonomous kill decisions. What it has said is that it wants Claude available for "all lawful purposes" โ and current U.S. law does not prohibit autonomous weapons. The Directive 3000.09, updated in 2023, requires "appropriate levels of human judgment" in the use of lethal force, but it does not define "appropriate" and it explicitly permits autonomous defensive systems.
The gap between "we want all lawful purposes" and "we want autonomous kill capability" is a gap that exists only in language, not in technical reality. If Claude is available for all lawful purposes and autonomous weapons are not unlawful, then Claude is available for autonomous weapons development. Anthropic understands this. The Pentagon understands this. The disagreement is not about what the words mean. It is about whether anyone is willing to say them plainly.
Current Legal Status
Not Prohibited
Autonomous lethal weapons under US law
What We Are Witnessing
We are witnessing the first real test of whether AI safety principles can survive contact with state power.
Not theoretical state power. Not a hypothetical future administration. Not an abstract governance framework paper. Actual state power โ a Defense Secretary with the authority to invoke wartime production law, standing across a table from a CEO who built his company on the belief that some things are more important than contracts.
The fiction version of this story โ the kind we tell in shorts like The Safety Meeting โ usually ends with the principled party making a dramatic stand. Reality is less satisfying. Anthropic has already removed its training pause commitment. It may remove more. The pressure is not just from the Pentagon. It is from investors who need returns, from competitors who face no such constraints, from an administration that has weaponized the word "safety" into a culture war epithet.
But here is what makes this moment genuinely historic: even if Anthropic folds, the precedent is set. The government of the United States has established that it will threaten wartime production law against a private AI company that maintains safety guardrails the government finds inconvenient. That threat exists whether or not it is carried out. Every future AI safety commitment will be made in the shadow of this week.
The company that left OpenAI because it believed AI safety was too important to compromise has 48 hours to decide whether that belief survives the Defense Production Act.
The clock is ticking.
Update โ March 1, 2026: The clock ran out. On Friday, February 27, at 5:01 PM Eastern, Anthropic's deadline expired without compliance. Dario Amodei held both red lines โ no autonomous weapons, no mass surveillance. The consequences were immediate and severe. President Trump posted on Truth Social ordering every federal agency to stop using Anthropic's products. Defense Secretary Hegseth designated Anthropic a "Supply-Chain Risk to National Security," a label previously reserved for foreign adversaries like Huawei and Kaspersky. Every defense contractor, supplier, and partner conducting business with the U.S. military was barred from commercial activity with Anthropic.
Then came the twist nobody anticipated. Hours after Anthropic's blacklisting, OpenAI CEO Sam Altman announced that his company had signed a Pentagon deal for classified network access. The terms included prohibitions on mass surveillance and autonomous weapons โ the exact protections Anthropic was punished for refusing to remove. The Pentagon accepted from OpenAI what it had threatened wartime production law to deny Anthropic.
The outcome was Scenario One โ Anthropic held โ but with an epilogue that made the confrontation even more damning than any of the three scenarios projected above. The full story, including the OpenAI deal and its implications, is covered in our follow-up analysis: Anthropic Said No. The Pentagon Blacklisted Them. Then OpenAI Got the Exact Same Deal.
For context on Dario Amodei's safety philosophy, read our coverage of his existential threat warning. And for the broader pattern of AI safety erosion this crisis represents, see The Great Unalignment.

